Unauthenticated SQL Injection in Weaver E-cology Mobile Plugin
CVE-2019-25776
Key Information:
- Vendor
Weaver Network Co., Ltd.
- Status
- Vendor
- CVE Published:
- 18 September 2026
Badges
What is CVE-2019-25776?
The Weaver E-cology mobile plugin is susceptible to an unauthenticated SQL injection vulnerability that enables remote attackers to execute arbitrary SQL commands. By manipulating the userIdentifiers GET parameter, attackers can exploit this flaw to perform UNION-based injections, effectively bypassing space-based filtering mechanisms. This breach allows them to extract sensitive information, including administrator credential hashes, from the underlying database. The vulnerability was noted to have been exploited as early as July 2022, as reported by the Shadowserver Foundation.
Affected Version(s)
E-cology *
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
